HIGH
CVE-2026-81090
CVSS
7.2
Description
The Gpx2Graphics WordPress plugin through 0.3 does not perform a CSRF check when handling file uploads, nor validate the type of the uploaded file, allowing attackers to make a logged-in administrator upload arbitrary files such as PHP via a CSRF attack, leading to Remote Code Execution.
Weakness (CWE)
CWE-352
Cross-Site Request Forgery (CSRF)
CWE-434
Unrestricted File Upload
EPSS Score
0.27%
Probability of exploitation in next 30 days
19.4th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.